CVE-2008-0611: SQL Injection
Published Feb 6, 2008
·Updated
SQL injection vulnerability in rmgs/images.php in the RMSOFT Gallery System 2.0 module for XOOPS allows remote attackers to execute arbitrary SQL commands via the id parameter.
Affected Software
2 affected components
RMSOFT Gallery System=2.0
Xoops Xoops
Event History
Feb 6, 2008
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-0611?
CVE-2008-0611 has a medium severity rating due to its potential for SQL injection attacks.
2
How do I fix CVE-2008-0611?
To fix CVE-2008-0611, update the RMSOFT Gallery System to a version that is not vulnerable to SQL injection.
3
What impact can CVE-2008-0611 have on my system?
CVE-2008-0611 can allow attackers to execute arbitrary SQL commands, potentially compromising the database.
4
Which software is affected by CVE-2008-0611?
CVE-2008-0611 affects RMSOFT Gallery System version 2.0 and the XOOPS content management system.
5
Is CVE-2008-0611 being exploited in the wild?
There have been reports of CVE-2008-0611 being actively exploited, so immediate action is recommended.